Turn a disputed agent action into a reviewable evidence case.
Bring together existing records, identify what they support, and give another team a clear way to inspect the findings and missing evidence.
Open-source preview: source link published with the public release.
- Question
- Did the rollback restore the flags config?
- Contradicted
- 1 finding
- Supported
- 1 finding
- Not established
- 1 finding
- Signature
- checked against the key you supply
One disputed action, read from the records.
A coding agent told a customer it had rolled back a configuration change. The deployment records disagree. The recipient needs to decide whether to accept the incident explanation or ask for more evidence.
The useful moment is seeing a plausible claim fail to become an established finding merely because a transcript says it happened. This page shows a summary; the synthetic case itself ships with the open-source preview as a signed bundle a recipient can check locally.
A claim is not a finding because a transcript says so.
Question, records, handoff.
Define the question
One question the recipient must decide, the time window, who receives the handoff and what is out of scope. Sources you expected but could not get are recorded, not ignored.
Review the records
Existing exports are kept byte-for-byte. Each finding cites the records it relies on, shows contrary records, and says what would settle it. Two views of one observation are not counted as corroboration.
Hand off findings and limits
The recipient opens the findings, follows each citation to its source, sees what verification checked and what it could not, and records a decision for a stated purpose.
The person deciding does not learn the investigator's tools.
They get five views: the question, the findings, the cited sources, verification, and their response.
- Files
- ✓ Match the manifest
- Signature
- ✓ Valid under the key you supplied. A key inside the bundle is never trusted automatically.
- Records rebuilt
- ✓ Re-derived from the included bytes
- Human review
- 2 of 3 findings reviewed by a second analyst
- Not checked
- Whether the sources are complete, whether the events occurred, who holds the key
- Decision
- Accept for a stated purpose
- Request more evidence
- Reject
- Defer
- Required
- A purpose and a reason
Because the response is bound to a specific revision, the investigator can tell when it goes out of date.
Where your evidence stays.
- Local-first software. Investigate runs on your machine or in your approved environment. It needs no account, makes no network requests and keeps originals unchanged.
- Assisted work under an agreed scope. For a scoped review we agree the question, sources, access, transfer and retention before any evidence is handled.
- No evidence upload here. This page has no upload form. Please do not send incident logs or credentials with a first request.
- Disclosure you control. Redacted handoffs can withhold whole sources or mask values. The recipient is told what was withheld and what therefore could not be rebuilt.
Two ways to start.
Review a disputed action with existing evidence
One bounded engagement. We agree the scope and a fixed fee with you before any evidence is handled.
- One case and one agreed question set
- Up to three agreed source types or exports
- Findings with their limits, and the checks that can be repeated
- A disclosed bundle and report for the recipient
- One recipient review session and one revision
- About five business days once agreed inputs and access are available
Not included: emergency containment, continuous monitoring, unrestricted collection, legal opinions or insurance determinations. The work is accepted against the agreed scope, not a favourable conclusion; “not established” is a legitimate outcome.
Record one workflow so future evidence is easier
The Verification Pilot adds signed records to one existing workflow, so the next dispute starts with records built to be checked. See an illustrative evidence case or verify a record.
Neither path requires adopting the whole PEAC stack up front.
Request a scoped review.
Tell us a little about the situation. We decide on any evidence transfer only after we agree the scope.
Status and limits.
| Topic | Detail |
|---|---|
| status | Investigate is a pre-release (0.2 preview). Case and bundle formats are versioned and may change before 1.0. It has not had an independent security audit. |
| supported inputs | Agent endpoint records (numbat), git history, GitHub audit logs, AWS CloudTrail, and any JSON Lines, JSON or CSV export with a field mapping. OpenTelemetry, ADR Sensor and PEAC records are experimental. |
| verification limits | A valid signature shows that the holder of a key the recipient trusts committed to the files. It does not establish who that holder is, when the evidence was collected, whether the collection is complete, or whether the recorded events occurred. Findings are attributed judgments within a stated scope, not proof. |
| security | Report vulnerabilities to security@originary.xyz with the subject “Security report: originary-investigate”. Please use synthetic data only. See our security policy. |
Bring the next disputed agent action to a decision.
Start with one question another team already needs answered. We will agree the scope before any evidence moves.